Responsible disclosure
Report a vulnerability
No system is perfect. If you identify a vulnerability in our systems and report it responsibly, we thank you and fix it as quickly as possible.
Bug bounty platform
For structured report tracking (real-time status, reference number, retest), use the AarMe platform.
Submit via AarMe →How to contact us
Send your report to [email protected]. We acknowledge receipt within 24 business hours and keep you informed throughout.
What to include
- - Clear description of the vulnerability
- - Steps to reproduce
- - Proof of concept if available (screenshots, logs)
- - Estimated potential impact
- - Your contact details if you wish to be credited
Scope
Tests must remain within the scope defined below and must not affect service availability.
In scope
- ✓ The cyberaar.io website and its subdomains
- ✓ The aarme.cyberaar.io platform
- ✓ Our open source tools published under github.com/cyberaar
- ✓ The public interfaces we operate
Out of scope
- ✕ The AarSOC production platform and client environments
- ✕ Third-party services and tools used by CyberAar
- ✕ Denial-of-service attacks (DoS/DDoS)
- ✕ Social engineering (phishing, vishing, etc.)
- ✕ Uncoordinated tests on production systems
Handling process
24 business hours
Acknowledgement
We confirm receipt of your report.
5 business days
Assessment
Vulnerability analysis, severity and impact qualification.
Based on severity
Fix
A patch is deployed. You are kept informed of progress.
Coordinated
Disclosure
Publication coordinated with you. Credit in the Hall of Fame if you wish.
Recognition
Hackers whose report is validated are credited in our Hall of Fame with their consent. Real name or alias: the choice is theirs. Recognition is currently public and honorific.
View the AarMe Hall of Fame →security.txt
Available at the canonical address in accordance with RFC 9116.
Contact: mailto:[email protected] Preferred-Languages: fr, en Canonical: https://cyberaar.io/.well-known/security.txt